Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.900exploits catalogados
35.840CVEs com exploração pública
24.695testados em laboratório
77.894 exploits
GitHub PoC20
the metasploit script(POC) about CVE-2021-36260
CVE-2021-36260CRITICALsob ataque03 nov 2021
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,
100RISCO
abrir
GitHub PoC6
POC for CVE-2021-34429 - Eclipse Jetty 11.0.5 Sensitive File Disclosure
CVE-2021-34429MEDIUM03 nov 2021
For Eclipse Jetty versions 9.4.37-9.4.42, 10.0.1-10.0.5 & 11.0.1-11.0.5, URIs can be crafted using some encoded characte
70RISCO
abrir
GitHub PoC6
Fuel CMS 1.4.1 - Remote Code Execution
CVE-2018-1676303 nov 2021
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca
60RISCO
abrir
GitHub PoC48
Exploitation code for CVE-2021-40539
CVE-2021-40539CRITICALsob ataqueransomware03 nov 2021
Zoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API authentication bypass with resulta
100RISCO
abrir
GitHub PoC1
Exploit Apache 2.4.50(CVE-2021-42013)
CVE-2021-42013CRITICALsob ataqueransomware03 nov 2021
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISCO
abrir
GitHub PoC4
Proof-of-Concept tool for CVE-2021-29156, an LDAP injection vulnerability in ForgeRock OpenAM v13.0.0.
CVE-2021-2915603 nov 2021
ForgeRock OpenAM before 13.5.1 allows LDAP injection via the Webfinger protocol. For example, an unauthenticated attacke
60RISCO
abrir
Exploit-DB
Eclipse Jetty 11.0.5 - Sensitive File Disclosure
CVE-2021-34429MEDIUMwebappsjava03 nov 2021
For Eclipse Jetty versions 9.4.37-9.4.42, 10.0.1-10.0.5 & 11.0.1-11.0.5, URIs can be crafted using some encoded characte
70RISCO
abrir
GitHub PoC
It is a simple tool to exploit local file include . vulnerabilities
CVE-2006-339203 nov 2021
Webmin before 1.290 and Usermin before 1.220 calls the simplify_path function before decoding HTML, which allows remote
60RISCO
abrir
Exploit-DB
OpenAM 13.0 - LDAP Injection
CVE-2021-29156webappsjava03 nov 2021
ForgeRock OpenAM before 13.5.1 allows LDAP injection via the Webfinger protocol. For example, an unauthenticated attacke
60RISCO
abrir
GitHub PoC
It is a simple tool to exploit local file include . vulnerabilities
CVE-2006-339203 nov 2021
Webmin before 1.290 and Usermin before 1.220 calls the simplify_path function before decoding HTML, which allows remote
60RISCO
abrir
GitHub PoC1
Test vulnerability of CVE-2020-3452
CVE-2020-3452HIGHsob ataque03 nov 2021
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2017-7494CRITICALsob ataqueransomware03 nov 2021
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allo
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-40539CRITICALsob ataqueransomware03 nov 2021
Zoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API authentication bypass with resulta
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2018-1676303 nov 2021
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca
60RISCO
abrir
VulnCheck XDB
infoleak
CVE-2020-3452HIGHsob ataque03 nov 2021
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-36260CRITICALsob ataque03 nov 2021
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,
100RISCO
abrir
Exploit-DB
Ericsson Network Location MPS GMPC21 - Privilege Escalation (Metasploit)
CVE-2021-43338webappsmultiple02 nov 2021
20RISCO
abrir
Metasploit600
Cisco RV Series Authentication Bypass and Command Injection
CVE-2022-20707CRITICAL02 nov 2021
Cisco Small Business RV Series Routers Vulnerabilities
85RISCO
abrir
Metasploit600
Cisco RV Series Authentication Bypass and Command Injection
CVE-2022-20705CRITICAL02 nov 2021
Cisco Small Business RV Series Routers Vulnerabilities
85RISCO
abrir
Metasploit600
Sitecore Experience Platform (XP) PreAuth Deserialization RCE
CVE-2021-42237CRITICALsob ataqueransomware02 nov 2021
Sitecore XP 7.5 Initial Release to Sitecore XP 8.2 Update-7 is vulnerable to an insecure deserialization attack where it
100RISCO
abrir
GitHub PoC
Exploit and Demo system for CVE-2021-3156
CVE-2021-3156HIGHsob ataque01 nov 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISCO
abrir
GitHub PoC
MovableType XMLRPC - RCE
CVE-2021-2083701 nov 2021
Movable Type 7 r.5002 and earlier (Movable Type 7 Series), Movable Type 6.8.2 and earlier (Movable Type 6 Series), Movab
60RISCO
abrir
GitHub PoC3
CVE-2021-22205-getshell
CVE-2021-22205CRITICALsob ataqueransomware01 nov 2021
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RISCO
abrir
VulnCheck XDB
local
CVE-2021-3156HIGHsob ataque01 nov 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-22205CRITICALsob ataqueransomware31 out 2021
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-22205CRITICALsob ataqueransomware31 out 2021
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RISCO
abrir
GitHub PoC13
CVE-2021-22205 RCE
CVE-2021-22205CRITICALsob ataqueransomware31 out 2021
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RISCO
abrir
GitHub PoC23
CVE-2021-22205 Gitlab 未授权远程代码执行漏洞 EXP, 移除了对djvumake & djvulibre的依赖,可在win平台使用
CVE-2021-22205CRITICALsob ataqueransomware30 out 2021
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RISCO
abrir
GitHub PoC21
XMLRPC - RCE in MovableTypePoC
CVE-2021-2083730 out 2021
Movable Type 7 r.5002 and earlier (Movable Type 7 Series), Movable Type 6.8.2 and earlier (Movable Type 6 Series), Movab
60RISCO
abrir
GitHub PoC2
PoC in single line bash
CVE-2021-22205CRITICALsob ataqueransomware30 out 2021
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RISCO
abrir
anteriorpágina 641 / 2.597próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.